Secure Peripheral Device Booting Secondary Operating System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage devices, such as USB flash drives, lack security, making it risky to store and boot operating systems from them, especially when lost or stolen, as they do not provide adequate protection for confidential data.

Innovation Solution

A secure peripheral device is developed that includes a memory with a device secure channel engine, cryptography module, challenge generation module, and verification module, allowing secure communication with a host computer and enabling the booting of a secondary operating system from a secure, encrypted area, using cryptographic technologies like AES and RSA to ensure data integrity and confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If operating systems are stored on USB flash drives for portability and energy efficiency, then device portability and energy consumption are improved, but security protection is worsened

Engineering Contradiction:
ImproveportabilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the USB flash drive into distinct functional modules: a secure element containing cryptographic keys and a file system area for storing operating systems. This segmentation isolates security-critical components from general storage functions, allowing the system to maintain portability while protecting sensitive data through physical and logical separation of security functions from storage functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure element as an intermediary component between the host computer and the stored operating systems. This secure element acts as a mediator that verifies bootloaders and operating systems before execution, providing security protection without compromising the portability benefits of USB-based booting.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic security measures are implemented in peripheral devices, then security protection is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts complex cryptographic functions from the main processor and places them in a dedicated secure element. This extraction isolates security-critical operations in a separate, specialized component, reducing the complexity burden on the main system while maintaining strong security protection through hardware-based cryptography.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element provides self-service cryptographic operations, independently verifying bootloaders and operating systems without requiring complex security management from the host system. This self-service capability simplifies the overall system architecture by making security autonomous and reducing inter-component complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8745365B2Method and system for secure booting a computer by booting a first operating system from a secure peripheral device and launching a second operating system stored a secure area in the secure peripheral device on the first operating system
Publication Date: 2014.06.03 KINGSTON DIGITAL INC
  • US8745365B2 patent drawing
  • US8745365B2 patent drawing
  • US8745365B2 patent drawing

AI summary

An operating system is booted from a secure peripheral device on a host computer. The secure peripheral device, which includes a memory, is communicatively coupled with the with the host computer. A first operating system is booted from the memory of the secure peripheral device. A secondary operating system is launched on the first operating system.